Cyber Security News

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside the company, detected on July 28 and confirmed the next day.

In a breach notification dated August 21, 2026, ASOS said it identified unusual activity involving customer accounts and launched an investigation immediately.

The retailer determined that an unauthorized third party may have used externally sourced credentials to sign in to affected accounts. The wording indicates a credential-stuffing or account-takeover scenario rather than a direct compromise of ASOS authentication infrastructure.

In such attacks, threat actors test previously leaked username-password pairs against other online services, relying on customers who reuse passwords across multiple platforms.

ASOS Warns of Customer Account Access

ASOS said the potentially exposed account information may include customer names, email addresses, delivery or billing addresses, telephone numbers, dates of birth, and details of linked social media accounts. The company said social media login credentials were not involved.

The accessed data may also include redacted payment card information, such as the cardholder name, the last 4 digits of the card, and its expiration date.

ASOS did not state that full payment-card numbers, CVV codes, or ASOS account passwords were exposed in the incident. On July 29, 2026, ASOS blocked access to the affected accounts and enforced mandatory password resets.

The company emailed customers on July 30, informing them that they would need to create new passwords before regaining access.
ASOS added that a small number of accounts showed evidence of suspicious transactions.

According to ASOS US Sales LLC, the transactions were blocked by security controls or canceled by its fraud team, with no further unauthorized activity detected after containment measures.

The incident highlights the continuing risk posed by password reuse. Even when a retailer does not suffer a direct data breach, credentials stolen from another service can enable attackers to access accounts containing personal information, addresses, and partial payment information.

Affected users should reset their ASOS password and avoid reusing it on other websites. Customers who used the same password on other services should change those passwords as well, starting with email accounts, banking services, payment platforms, and social media accounts.

Enabling multi-factor authentication where available can further reduce the likelihood of account takeover. ASOS also urged affected individuals to monitor payment account activity and statements for any unfamiliar transactions.

Customers can obtain free annual credit reports through the three major US credit reporting agencies: Equifax, Experian, and TransUnion. They may also consider placing a fraud alert or credit freeze on their credit files if they suspect identity misuse. The notification states that the company’s notice to California residents was not delayed by law enforcement.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…

5 minutes ago

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…

6 minutes ago

AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting

AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…

10 minutes ago

Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number

A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium…

15 minutes ago

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is…

1 hour ago

Microsoft August 2026 Update Breaks When Generating PDF/XPS Content

Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures…

1 hour ago